How a $320/month Phishing Service is Hijacking Microsoft 365 Sessions

·
How a $320/month Phishing Service is Hijacking Microsoft 365 Sessions

Cybersecurity researchers reveal NovaCookies, a $320/month phishing service that hijacks Microsoft 365 sessions by impersonating DocuSign notifications, capturing live authenticated access.

Cybersecurity researchers just pulled back the curtain on something that should make every business professional pause. There's a new phishing toolkit in town called NovaCookies, and it's playing a surprisingly sophisticated game. It's what we call an adversary-in-the-middle attack, but you can think of it like a perfectly positioned con artist who intercepts your conversation without you ever knowing. Here's the unsettling part: this isn't some hobbyist's project. Island, the cybersecurity firm that uncovered it, reports it's a subscription-based service. For $320 a month, bad actors can essentially rent this phishing platform. That price tag alone tells you this is professional-grade trouble. ### The Devious NovaCookies Method So how does NovaCookies actually work? Imagine you get what looks like a legitimate DocuSign notification email. You click the link, expecting to sign a document. Instead, you're silently routed through a proxy server controlled by the attacker. This server sits between you and the real Microsoft 365 login page, watching everything. You type in your credentials, and they look right. The page looks right. But in the background, NovaCookies is capturing your authenticated session. It's not just stealing your username and password; it's stealing the entire "key" to your account after you've already unlocked the door. This means attackers can bypass security measures like multi-factor authentication that would normally stop them cold. - It impersonates trusted services like DocuSign to trick users. - It acts as a malicious proxy during the sign-in process. - It captures the live session token, not just login credentials. - It operates as a service, lowering the barrier for cybercriminals. ### Why This Changes the Threat Landscape This is a significant shift. We've moved from scattered phishing attempts to a scalable, service-based model. It's phishing-as-a-service, and that's a worrying trend. The affordability means more attackers can launch more sophisticated campaigns. A quote from the research report drives this home: the service is characterized as "a subscription-based phishing platform" designed for consistent, reliable attacks. The target is clear: Microsoft 365 sessions. Given that millions of businesses rely on this suite for email, documents, and collaboration, the potential damage is enormous. A compromised session can lead to data theft, further phishing attacks from a trusted account, or even ransomware deployment. ### What This Means for You and Your Team First, don't panic. But do get proactive. This attack relies on deception at the email level. That's where your first line of defense needs to be. Training is non-negotiable. Your team needs to be skeptical of every email, even those that look familiar. Hover over links to check the actual URL before clicking. If something feels off about a DocuSign or Microsoft 365 email, verify through a separate channel—like a direct phone call to the sender. For IT administrators, this is a call to reinforce security policies. Consider implementing stricter rules for external email tagging. Look into advanced threat protection solutions that can detect these proxy-based login attempts. Session monitoring is also crucial; unusual login locations or simultaneous sessions from different countries are major red flags. Ultimately, the rise of tools like NovaCookies reminds us that the human element is often the weakest link. Technology can do a lot, but cultivating a culture of security mindfulness is your best long-term defense. Stay curious, stay cautious, and keep those sessions secure.